hyperswapv3[.]pages[.]dev
“HyperSwap V3 – Advanced Decentralized Exchange”
This domain, hyperswapv3.pages.dev, is flagged as an active phishing infrastructure designed for brand impersonation and cryptocurrency theft. Analysis indicates it targets users of Across Protocol, a decentralized bridging platform, by presenting itself as HyperSwap V3, an advanced decentralized exchange. The site employs social engineering tactics to trick victims into connecting wallets, likely deploying a crypto drainer script to siphon funds upon interaction. No specific drainer kit has been conclusively identified, but the operational pattern aligns with known wallet-draining campaigns targeting DeFi users. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 188.114.97.3, hosted on Cloudflare’s AS13335 network in the United States. It was registered through Cloudflare on August 23, 2025, and uses an SSL certificate issued by Google Trust Services (WE1). The page title, 'HyperSwap V3 – Advanced Decentralized Exchange,' mirrors legitimate DeFi branding to enhance credibility. As of the latest scan, VirusTotal reports 1 out of 95 security vendors flagging the domain, while one additional blocklist has recorded its malicious activity. No detections were reported by Google Safe Browsing at the time of analysis. The domain remains active and poses a high risk to users of Across Protocol and similar DeFi platforms. While one security vendor has blocked access, the limited detection rate suggests the infrastructure may still evade widespread filtering. Users are advised to verify domain authenticity before interacting with any DeFi-related websites, particularly those prompting wallet connections. Wallet addresses or transaction hashes associated with this domain should be treated as malicious and reported to relevant blockchain security platforms for further tracking.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
Джерел: 10 · синхронізовано 09.08.2026
Хронологія виявлення
Збережені спостереження у хронологічному порядку.
-
Cloudflare Radar
Cloudflare Radar: уперше зафіксовано як https://radar.cloudflare.com/scan/03a8cbaf-8a8e-460c-b286-3306db47f804
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of hyperswapv3.pages.dev · checked Mar 2, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога